CVE-2003-0907
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 21.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 21.85% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- microsoft/windows server 2003 · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.htmlBroken Link
- http://marc.info/?l=bugtraq&m=108196864221676&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/o-114.shtmlBroken Link
- http://www.idefense.com/application/poi/display?id=100&type=vulnerabilitiesBroken Link
- http://www.kb.cert.org/vuls/id/260588Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10119Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA04-104A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15704Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904Broken Link
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.htmlBroken Link
- http://marc.info/?l=bugtraq&m=108196864221676&w=2Third Party Advisory
- http://www.ciac.org/ciac/bulletins/o-114.shtmlBroken Link
- http://www.idefense.com/application/poi/display?id=100&type=vulnerabilitiesBroken Link
- http://www.kb.cert.org/vuls/id/260588Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/10119Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA04-104A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15704Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.